Sign inSign up
Image Reflector Controller

dhi.io/fluxcd-image-reflector-controller

fluxcd image reflector controller 1.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.2-debian-dev, 1.2-debian13-dev, 1.2-dev, 1.2.5-debian-dev, 1.2.5-debian13-dev, 1.2.5-dev

Index digest:

sha256:98adc4f9483676cac1582f53c65d087f18537753589446ab93c96982d1e92eb0

Manifest digest:

sha256:d6edd29ca2d99dfce37ba68dc2d0fff77caf2fa4a025449ef6e57e772bf65c89

Size

56.22 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-image-reflector-controller:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-image-reflector-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-image-reflector-controller@sha256:67f7834e2c6a454517f7f06c67b5cc339eecfece6cbe0500666b4510825421ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:92c2daaa0101e6deed8e1b0d5e3649cbd6faff2d75a8100b617ff121d6a661e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:d79155dc107610b3870179ba2fc1f25602983449b00310b58d00132c73b910c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-image-reflector-controller@sha256:ae0884ac7dad49e2c5ee362c8a365484ea9ff5cb44d9470d493bf1cab0544d00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-image-reflector-controller@sha256:e935a11caedb055968b2d2e7004a6d5987f3f59560de1f35dd4c9ff03889f508
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:de1d0a0cee7326032359207179a52ca634eb13602f704114e1f0133772cc4546
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:16b5f62ad1877cd7cecaa97553c8eb30579eaaf3f17754e3502531c36c862a0a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:1c2deba469f910e5e8d12953c981d82920d292d054b19c18696b8d373d40b543
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:52b080288ca600885bb251b1d9a5d283fa3b53cbdc43358ab397590e6ab41f87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:51bfb28c670ff48cc31f09bec2a288f10c3f9709c70ea848c61c2363bfc8068e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-image-reflector-controller@sha256:dc725e63710b045e969fdad425699ecbae8917202a210346f2a4b816587d9190
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-image-reflector-controller@sha256:30d215d05bcf5dc2c050c51241e7133268f8fb16c94008b1a4834510b5ba3358
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-image-reflector-controller@sha256:5a5282ded0cbc6b77851796780914b1547a084f755be468e27bda9efd27679c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-image-reflector-controller@sha256:888ca3785047454048b41968da7c6261fc0e56f14ee6c73cedba1681dd9c3dd5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-image-reflector-controller@sha256:7c33364971461635009e834764b629d043960d1f497b069286f2b225b2678d00